Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

It was recommended by MS (I believe, I'll double check though) to not setup DNS roundrobin anymore on 2012 and beyond, I could have misread I'll go back and look through.

Adbot
ADBOT LOVES YOU

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

NevergirlsOFFICIAL posted:

What's a good step-by-step guide that can explain to me how to set up 2FA in my Windows environment? I have googled, read some old blog posts, and still don't feel like I have a good understanding.

My requirements:
1. Require 2FA when user is not physically on the LAN - this means when they are connecting to SSLVPN or RDS
2. Require 2FA when accessing sharepoint via webdav or https (from the WAN)

For #1 I have a 2FA built in to my existing SSLVPN solution (sonicwall sra). RDS I was looking at Duo but Duo doesn't plug in easily to sharepoint per my understanding.

I get there's something I can do with ADFS that would involve extending my domain to Azure. But I have no idea what that looks like for the user.

We just rolled AuthAnvil 2FA for RDS, it was only a minor pain in my rear end, but we've only been fully turned on for a week or two, so I'm not sure if things are going to explode after a month or two. Unsure about sharepoint capability, but it's very affordable; will require at least 1 VM dedicated, possibly 2 I forget, but you'd want 2 anyway for redundancy, does hook into AD easily as well.

We previously used safeword, I loved safeword, I'm not sure how well it hooks into sharepoint though, or if they're still around, once we switched from 2003 to 2012 we decided to change to authanvil. Unsure about sharepoint capability, hooks into AD easily, does require 2 VMs minimum for redundancy, and I'm not sure regarding pricing.

RSA is also good, my client uses it for VPN, it's loving expensive as hell though.

All of these SHOULD have plenty of documentation to get you well on your way to getting stuff working.

MF_James fucked around with this message at 18:02 on Sep 14, 2016

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

peak debt posted:

Does anyone know how to programmatically change a file type association in Windows 10?

Under Windows 7 it was a simple case of exporting/importing a reg file. But if you try the same thing in Windows 10, then after the next reboot you get a system tray popup "There was a problem with a file type association" and it gets reverted to the default setting.

Two things I've tried so far are:
- Only importing the "HKEY_CLASSES_ROOT\filetype" key (not the "HKEY_CLASSES_ROOT\.ext" one) then using the command line application "assoc .ext=filetype" to set the default setting.
This seems to work at first. If you run the "assoc .ext" command the correct application is displayed. But if you doubleclick a file, the new application is only offered as a choice and there is no checkbox to remember your setting so it opens once with the new application, and then resets to the default again.
- Using the "Dism /Get-DefaultAppAssociations" and "Dism.exe /Import-DefaultAppAssociations" commands. Here, the problem is that you cannot import single app settings, you can only overwrite the entire set of default apps. So if you run this on a computer with nonstandard apps installed, you are basically guaranteed to gently caress up things by deleting file type associations.

The reason I have to do this is that we have ancient .tiff files that only open in some lovely image viewer from the 90s.

Look for default associations.xml, you can't manually modify a bunch of stuff in the registry anymore, the registry is hashed and it will revert the next time it loads.

https://www.loginvsi.com/blog/login-vsi/518-fixing-default-file-type-associations-in-windows-10

This worked in server 2012/windows 8, and i believe still works in windows 10

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

quote:

We recently took on a new client, and I flew out there to re-IP their entire office about a month ago. They have two domain controllers called DC1 and FS2.


CLAM DOWN posted:

:stare:

You know that 2003 is very much end-of-life, right? And has been for a while? And shouldn't be allowed near a network connection?

Clients.txt

I'm not saying it's good or OK, but this is what you deal with in an MSP, your clients are cheap as gently caress and everything is awful. I would hope that his company made them aware of this and the risks associated.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

127.0.0.1 and then other DCs.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Eschatos posted:

I'm not seeing a specific GPO/AD thread, so hopefully this is the right place to post this question:

How do I go about configuring a group policy to apply to all computers in a given OU? Googling brings up a whole bunch of answers recommending loopback processing for folks trying to apply user configuration settings to computers, which is not what I'm trying to do. The straightforward alternative is setting up new security groups for all PCs but that strikes me as a waste of time. These PCs are already in dedicated OUs for all the workstations in a given location. Ideally I'd be able to just link the GPO in question to all these OUs and set security filtering to apply to everything, but there doesn't seem to be any "Authenticated Computers" equivalent to Authenticated Users.

Eschatos, if you apply a GP to an OU, it will apply to everything in that OU*. Computer configuration stuff will apply to computers, user config stuff to users.

*Unless otherwise specified by filtering of some kind.


Feel free to hit me up on IRC, I'm typically in it all day (you know which one!)

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

lol internet. posted:

Details on this magical IRC channel please.

haha just an IRC channel for a game we both play, nothing special.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Dunno where else to ask, but here goes...

Just got "tablets" dumped on my lap. We have about 50-60 windows 8.1 tablets out in the field, previously they were all 'hand' configured. The guy before me created a policy file that he manually imported on all the machines as well as a few other manual steps prior to that. Well, we are getting windows 10 tablets now (even replaced tablets come back with 10 and not 8.1, it's not the same tablet, but I figured we would get what OS we had previously...) and I'd like to make this process not poo poo.

Basically I need to do a few things:

1) disable built-in admin/guest accounts
2) create another admin account (named the same across all systems)
3) create a lesser privileged account that will essentially operate in a kiosk type mode
4) lock down said account
5) install our monitoring solution
6) patch machine

Steps 1-4 are what i want to stream line, 5 and 6 can be done manually for now.

I typically don't handle client type devices, just servers.. a lot of them, but the way we handle spinning up servers will not work for what I'm doing.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Zaepho posted:

What do the desktop guys use for imaging? MDT/WDS or MDT and SCCM would work quite nicely for these. Everything you're talking about can be rolled into a task sequence.

Yeahhhhhhhhhhhhhhhhhhhhhhhhhhhh........................

we don't do any desktop stuff except internal poo poo for like 20 users. I figured that was going to be the answer though.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Yeah they aren't attached to a domain sadly. I'll probably create a new registry file and then script everything else that I can. Updates are handled by our monitoring solution (N-Able), so that's no biggie, I'll just script the import of the policy file, the install of n-able and a few other things so all someone (hopefully) has to do is move a folder onto the device and then run the script inside.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Could make sure they can see/have permissions on that specific folder in the sysvol. Have you tried unjoining/rejoining and see if that has any effect? Also, those machines aren't being filtered with WMI or security filtering right?

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Wrath of the Bitch King posted:

I've gone through most of the common steps, the scope is highly unusual.

You can build a brand new 2008 SP2 server and attach it to the domain. It will initially pull policy, but after that initial pull it becomes completely unable to change any of those policies ever again. No updates, no removals, nothing. Only 2008 SP2.

No filters are in place, these servers share a common OU/container with other server variants and are subject to identical policies. Guess I'll keep digging.

My guess is there is an ADMX template that 2008 SP2 is choking on; GPResult is displaying the normal results you'd expect for a working instance barring any changes made after the initial pull. User policy is functioning, but machine policy isn't.

What if you blow away the machine policy, does it pull it down again?

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Well, he DOES have other (non 2008) systems that pull that same policy just fine, although I've never dealt with corrupted sysvol so I'm not sure of the exact behavior, I would assume NOTHING would be able to read from the folder/subfolders that were affected though.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

I've had that happen, the policy was in the middle of the order and *edit* correction, the policy was corrupted after the last time someone modified it, every policy would process up to that one, then GP crapped out so nothing after processed.

MF_James fucked around with this message at 05:11 on Oct 14, 2016

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Super Slash posted:

Is there some kind of information source about best practices for Windows 10 group policies?

I've got some machines in which shipped with Windows 10 Pro and need to make them as non-lovely and barebones as possible, so our users don't come up with a million questions about how stuff works. I've done the basic stuff like turn off cortana, telemetry, security enforcement, but I'm having a hell of a time just setting a company lock/login screen.

Of course the next step is to deploy standard imaging, but I need the budget first.

http://www.grouppolicy.biz/2012/11/how-to-use-group-policy-to-change-the-default-lock-screen-image-in-windows-8/

You can also customize the start-menu, by exporting a startmenu layout from one computer and then applying it via group policy (it's an xml file). I could dig up my information on that if you need. I had to do some work to get win10 tablets locked down, I got about 95% of the way done and the work was scrapped...

As far as a single spot to find a ton of info? I couldn't find one, I dug through dozens, maybe even 100+ websites to gather all the stuff I did.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Eschatos posted:

Office 365 admins, I got a question for you. I've recently discovered that several users at my company have email addresses that are completely desynced from Active Directory. Their email has its own separate password, is listed as In cloud, and their AD account shows up separately as an .onmicrosoft.com address instead of our domain.



Anyone know of any way to merge these two so that the proper domain email syncs with AD? My best guess right now is to export, delete and reimport. I'm hoping there's a method that's less of a pain in the rear end.

I just had to fix one of those. I setup a user but screwed up because they have a .local domain and i let that sync.

I changed it in AD to be @contoso.com instead of @contoso.local

Then went to AD and manually editted the user and removed the .onmicrosoft.com and just had their user as @contoso.com, that seems to have fixed it (although this was a whopping 20 minutes ago, but their password to O365 was definitely their AD password because the user was able to log in)

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

tadashi posted:

I'm looking for a step-by-step on how to migrate the domain time server. While I was migrating my PDC to a new physical server a while back, I made the time server to be a tertiary domain controller (literally a domain controller of last resort that's a virtual machine) and now I cannot for the life of me get our workstations to stop syncing their time to that backup domain controller instead of the PDC. This is an issue because the backup domain controller is on a Hyper-V VM so its time is not reliable (this was only supposed to be this way for a couple days).

I have added a scope option to DHCP to make the PDC the time server and I setup the registry entries on the PDC to make it a time server. I went to the backup DC and, i think, changed all the registry settings that would make it the time source instead of the PDC. All of the servers in our environment except for the one that was the backup domain controller will sync with the PDC. All the workstations and the backup domain controller sync to the backup domain controller.

:argh:

E: Also, I looked at our Group Policies and there isn't even an option for time server in there (it has to be corrected via hotfix) so I did not make any group policies about the time server.

Ahh this should help you, what version of server are you running? https://blogs.technet.microsoft.com/nepapfe/2013/03/01/its-simple-time-configuration-in-active-directory/

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

tadashi posted:

Server 2012. That's the other issue is that most guides are written for 2003 so some commands can be a little different.

Most things (that I've noticed) have remained the same, you might need to ? and perhaps google slightly more, but the linked article should get you to where you want, I mean basically you want to tell the PDC it's the da boss (and have it get NTP from somewhere?) and then have everything else sync to it.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

GreenNight posted:

What do you guys use for enterprise 3rd party patch management? Don't care about the costs, just want it to be easy to use.

N-Able is our monitoring solution, it also handles patching and can do other stuff depending on what you pay for. The patching sucks, I wish we just dropped a WSUS server at all our clients :(

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Gozinbulx posted:

Can anyone point me to a good guide/outline of group policy settings I should use to limit and hopefully seriously stymie the proliferation go malware/bloatware poo poo on workstations?

What sickening said. I would look up Microsoft's recommended baseline group policy, but Sickening gave you the stuff to get started with.


Depending on your size/budget you can use appliances or applications to do email and content filtering. I work with a lot of fortigates/fortinets that act as firewalls and content filters, they seem to do a good job at both, but I'm not a security guy so perhaps there are better ways to go about it, and obviously it depends on your current environment.

MF_James fucked around with this message at 22:44 on Jan 23, 2017

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Has anyone really used LAPS yet? (https://technet.microsoft.com/en-us/library/security/3062591.aspx)

Our current setup is ERPM and we disable built-in admin/guest, then create a separate admin and utilize ERPM to manage/rotate the password as needed. Moving forward we would disable guest and then let LAPS manage the built-in admin password. This will save our client roughly 200K a year, so it's something that is getting pushed, provided we don't hit showstoppers.

For those that have used it, any issues/gotchas/whatevers?

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Perhaps we aren't going back to the built-in admin account. Initially I thought LAPS could ONLY handle the built-in, but perhaps it has changed since I last looked at it (it's been a while). I am not specifically involved in the project, but figured I'd see what others have experienced.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

anthonypants posted:

Make a new machine and promote it to a domain controller.

Yeah this. Stand up a new DC immediately, let replication happen and then hand all FSMO roles over to it then demote the other one and trash it.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Ugh I'm saddened I even have to ask this, but I can't find the answer, my google-fu is failing me. Client bought office 365 home premium and wants to install it on a few work machines, is there some sort of limitation on that install so that it won't go onto domain machines?

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

anthonypants posted:

There is no such limitation.

Alright then, we have some other issue, thanks.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Thanks Ants posted:

You're violating the terms of the license by using it commercially, which you probably don't want to assist your client with if you're an MS partner.

Not an MS partner, and I'm aware. Already have an email from my boss saved where I brought that up and he said "Just Do It"

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

You need to raise a huge stink to whoever manages support (or whoever your boss is) and mention how much time this will take across your whole department versus one guy fixing it.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

I've heard it recommended to just go for the newest exam, otherwise you have to take an upgrade exam anyway to get to 2016 level and stay current.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Do they not have help files loaded? Cisco makes you "memorize"/type commands etc but help will also be available in the CLi*


*Unless there is an issue with the sim OR you're on the wrong path

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Sickening posted:

Just curious, but have you ever taken a MS exam before?

No, I was assuming they were having you write powershell commands not doing something as dumb as multiple choice "Spot the letter that is swapped around" stupidity, but obviously I am dead wrong.

At some point I would like to take MCSE, but cisco comes first.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

lol internet. posted:

Anyone know what the minimum amount of servers requires for RDS remote app deployment is? And does it require AD? This would be for one or two users.

This seems like a 10lb sledge for a finishing nail. Do you already have RDS farm running and you just need a few people to run remote apps?

I mean you CAN do a single server deployment, you just stick all the roles on the single server. This could be a guide (note: I have not read it but it talks about single server RDS deployment): https://msfreaks.wordpress.com/2013/12/09/windows-2012-r2-remote-desktop-services-part-1/

So, you really need 2 servers anyway though, because, yes, you do need AD and SQL (which CAN be installed on a DC with some fuckery).


Really, you should probably not be trying to do this for 2 users. What problem are you trying to solve?

MF_James fucked around with this message at 03:25 on Mar 10, 2017

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

lol internet. posted:

RDS alone doesn't require sql does it? I don't recall using it on a 2012r2 RDS.

Correct, my fault, but you will need access to a domain controller. So you're still stuck with devoting 2 machines to this. Well, I'm assuming, since you asked about DCs to begin with...

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

.local still works fine, it's just slightly extra work, but nothing horrible, we have 2 clients with .locals. I would NEVER EVER go through renaming their domains at this point.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

CLAM DOWN posted:

.local is only excusable if it's a forever private and cut-off network/domain

Have you tried to rename a domain before?

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

CLAM DOWN posted:

Yup, it's a terrible idea, doesn't mean .local is good though!

I don't think anyone was advocating creating a domain with .local, but I'm not going to go through the awful that is renaming a domain (especially because MSP land so billable work and all that)

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Thanks Ants posted:

If you don't see any reason why legitimate traffic would come into your network from Russia, China etc. then is blocking it all at your firewall an option?

We block pretty much all countries outside the US on our inbound firewall rules for most of our customers. It's the easiest route to go, though none of them have legitimate business need for inbound connections from outside the US, so that makes it easy.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Hopefully someone else has dealt with this. I have an RDS farm, 2 terminal servers that some people log into via thin clients and some people have desktops that they are served remote apps to and we use DNS round robin. Currently I have one of the terminal servers in drain mode and everyone that is on network is getting pushed over to the other terminal server just fine, but I have VPN users that are still hitting the loving drained server so they can't log in. Is this a local DNS cache issue, or is something else going on? The remote users are using links provided to them that connect to the farm name, not directly to a server, but it keeps having them hit the drained server and I can't figure out why.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

BangersInMyKnickers posted:

Are you not running a broker server? That's the only way I know for it to properly coordinate sessions and forward them off a drained server reliably.

yeah we have a 3rd server handling broker services and licensing.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

I'm assuming DNS as everything works fine when not drained and they hit both hosts without issue. Thanks I'll bark up that tree once I can get in touch with one of these guys.

Adbot
ADBOT LOVES YOU

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Wrath of the Bitch King posted:

I'm still at a loss of where to start, exactly. It all seems a little overwhelming.

Do I start with picking a language and coding?

Do I start with tools like Packer/Terraform and understand their utilization in in cloud deployments?

Etc. and so on. The paradigm shift coming from traditional imaging and admin work is huge, and there's no crossover between the two beyond maybe some powershell.

I am in the same boat, my assumption is start by learning a language (I'm rolling python since it's popular and somewhat easy, especially if you've coded/scripted before) so you at least have a grasp on it, then jump into doing stuff on AWS/wherever. It was Methanar that posted a good write-up in the Working in IT thread, I don't have it up since I'm at work, but I've got the post saved at home if you can't find it, it's likely within his last 10-15 posts in that thread.

Because I'm retarded and forget how to link to specific posts:

https://forums.somethingawful.com/showthread.php?threadid=3653857&userid=204963&perpage=40&pagenumber=13

content of said post from Methanar posted:

What do you want to do?

I know that's a hard question to answer in the very beginning when you're not even entirely sure what the hype behind a particular technology is. I know nothing about your work environment or what your workloads are.

The power of containers is the automation tooling surrounding them. A plain old docker file running somewhere doing something being handled by systemd or whatever is actually pretty boring. I guess you might be able to make things a bit quicker by pulling down an haproxy container file from a public repo or whatever, but that's not the point.

Containers are great because they are the perfect primitive for building upon. What can be built ontop of containers? Immutable infrastructures, applications that can be deployed with all of their dependencies bundled with them, intelligent automatic resource scheduling, CI/CD pipelines, blue/green deployments off the top of my head.

The reality is if you're the kind of windows admin that I was, the value isn't there for you. Whatever it was that I did at previous jobs had literally zero use whatsoever for any of the concepts I just named. But maybe you're not the kind of windows I was, or you don't want to be. If you don't know what you want out of containers, or more importantly, the larger superset that containers are part of, other than that you want them; that is is perfectly okay.

A good place to start is to just make an account with either Google Compute platform or AWS. I'm actually going to recommend GCP here. I've been spending an awful lot of time recently immersed in GCP and it's very approachable compared to AWS. Kubernetes is also a Google product and thus is as first class citizen in GCP.

Great, you've made your account and are ready to start. Here is where that hard question comes in, what do you want to do. You're entering here ~Devops~ territory. You're not a windows admin anymore working with pre-packaged applications that are built for you. In Devops land being familiar and comfortable with software development is now an unavoidable necessity because delivering software that your organization produces is the point. So, naturally I guess the first thing to do is write a hello world micro-service application in the language of your choice. Golang, nodejs, python, ruby. Pick one and follow a guide on the internet.

Your hello world application can be simple, but use many pieces. Find a guide that involves multiple external components, maybe Redis or MySQL. Say ultimately you get 5 pieces to your new micro-service oriented distributed system. A front end, a piece dedicated to db access, something in the background that handled logging, maybe an internal request router, maybe something that procedurally generates a bitmap image, a message bus, redis and your DB daemon. Now, it's time to publish your application to the world. Each micro service is self contained and stateless which means they are a perfect fit for being in a container!

But wait, writing and developing code is hard. The code you write sucks and is actually full of bugs. What a perfect time to set up a CI/CD pipeline to make your software developer lives easier. Like any good developer you've been using Git as your version control system. Why not build a Jenkins server, in a container naturally https://hub.docker.com/r/jenkins/jenkins/, that will automatically build, compile and test your code for you every time you commit a branch? Jenkins can spawn MORE containers where your code will be built and be ran against synthetic tests you write to be sure you haven't introduced regressions. https://techbeacon.com/beginners-gu...ipeline-jenkins

Finally: you have a sane build system like any good developer, your code is bug free and ready for the world. Maybe you start off pushing the containers produced by Jenkins to your VMs by hand, because hey, theres only like 7 of them right? But you continue to grow and your app is pretty popular. It's starting to get hard and expensive to provision all the necessary machines you need to power your bitmap generator. You notice that your application has clearly defined times of the week of peak traffic. Wouldn't it be great if you could size the amount of compute resources you were buying from Google according to your real time traffic load? Enter: Kubernetes.

Kubernetes is a Big Deal. It's actually the technology that is underlying Google's Container Engine that's been open sourced.
Kubernetes, is a system for managing containerized applications across a cluster of nodes. Explicitly designed to address the disconnect between the way that modern, distributed systems are designed and the underlying physical infrastructure. Applications comprised of different services should still be managed as a single application (when it makes sense). Kubernetes provides a layer over the infrastructure to allow for this type of management. Scaling traffic up and down according to load. Logically grouping containers together, software defined networking and so much more are now possible.

Logically grouping containers together: maybe it just always makes sense for your bitmap generated to have 4 micro-services in running on the same host to minimize InterProcess Communication (IPC) latency. Kubernetes can do that. Maybe you always want X amount of microservices running on different underlying hardware to be resilient to datacenter mishaps. Kubernetes can do that. Since Kubernetes is now infront of your apps providing load balancing services, you can do things like blue/green deployments. Lets say parts of your application are stateful, how do you deploy new code? How about just building an entire new parallel environment that you send new users to while the existing stateful sessions just naturally drain off of the old environment. How about running as many versions of the code you write at once?

Containers are the fundamental unit making up larger systems. This is why saying you want to do containers or devops is meaningless. Because it's not something you apt-get install or curl | bash. Devops is to technology-focused companies as the scientific method was to chemists.


This is why containers and the Devops concept/mentality/paradigm/thing is useless to the kind of internal IT windows admin that I was. We didn't write code, we didn't open source software that we were empowered to orchestrate. Running large distributed systems was not our business. If you want to 'get in on this container thing' you need to evaluate what you're doing with it. Maybe you're not satisfied with being an internal windows admin anymore and thats why you're interested. Excellent! The new world of online services is big and scary, but it's here, and more accessible than ever. Join a mailing list! Go to the Kubernetes github and open every link in a tab and read it all! Write your hello world app! Learn to program! (I've got another huge rant about 'learn to program') Read my posts!

MF_James fucked around with this message at 16:57 on Oct 31, 2017

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply